|
1861
|
7.8 |
HIGH
Local
|
-
|
-
|
A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM
|
CWE-362
Race Condition
|
CVE-2026-7432
|
2026-05-13 01:38 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1862
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.
|
CWE-749
Exposed Dangerous Method or Function
|
CVE-2026-8109
|
2026-05-13 01:38 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1863
|
7.8 |
HIGH
Local
|
-
|
-
|
Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-8110
|
2026-05-13 01:38 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1864
|
8.8 |
HIGH
Network
|
-
|
-
|
SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.
|
CWE-89
SQL Injection
|
CVE-2026-8111
|
2026-05-13 01:38 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1865
|
8.8 |
HIGH
Network
|
pi-hole
|
ftldns
|
Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL accepted newline charac…
|
CWE-93
CRLF Injection
|
CVE-2026-39849
|
2026-05-13 01:27 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1866
|
8.8 |
HIGH
Network
|
anthropic
|
claude_code
|
In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft a malicious reposi…
|
CWE-20 CWE-77 NVD-CWE-noinfo
Improper Input Validation Command Injection
|
CVE-2026-40068
|
2026-05-13 01:21 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1867
|
6.5 |
MEDIUM
Network
|
langgenius
|
dify
|
Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplyin…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-41950
|
2026-05-13 01:20 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1868
|
7.5 |
HIGH
Network
|
openmrs
|
openmrs
|
OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResources/{moduleid}` endpoint is vulnera…
|
CWE-22
Path Traversal
|
CVE-2026-40075
|
2026-05-13 01:18 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1869
|
6.5 |
MEDIUM
Network
|
getgrav
|
grav
|
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restrictions by utilizing …
|
CWE-863
Incorrect Authorization
|
CVE-2026-42610
|
2026-05-13 01:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1870
|
8.9 |
HIGH
Network
|
getgrav
|
grav
|
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection of svg element. The XSS can further be escalated t…
|
CWE-79
Cross-site Scripting
|
CVE-2026-42611
|
2026-05-13 01:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|